| From: | Simon Riggs <simon(at)2ndquadrant(dot)com> | 
|---|---|
| To: | Magnus Hagander <mha(at)sollentuna(dot)net>, "Marc G(dot) Fournier" <scrappy(at)postgresql(dot)org> | 
| Cc: | pgsql-www(at)postgresql(dot)org | 
| Subject: | Re: [ANNOUNCE] CRITICAL RELEASE: Minor Releases to Fix DoS | 
| Date: | 2006-01-09 09:29:12 | 
| Message-ID: | 1136798952.21025.344.camel@localhost.localdomain | 
| Views: | Whole Thread | Raw Message | Download mbox | Resend email | 
| Thread: | |
| Lists: | pgsql-announce pgsql-general pgsql-www | 
On Mon, 2006-01-09 at 02:33 -0400, Marc G. Fournier wrote:
> PostgreSQL patch versions 8.1.2, 8.0.6, 7.4.11 and 7.3.13 are available 
> today.  The fixes in the 8.1 and 8.0 branches are critical, especially for 
> Windows users, and users of these branches are urged to update at their 
> earliest opportunity.
> 
> One critical fix repairs a denial-of-service vulnerability: on Windows 
> only, the postmaster will exit if too many connection requests arrive 
> simultaneously.  This does not affect existing database connections, but 
> will prevent new connections from being established until the postmaster 
> is manually restarted.  
> The Common Vulnerabilities and Exposures (CVE) 
> project has assigned the name CVE-2006-0105 to this issue.
No they haven't: there is no such CVE number assigned, nor is there one
pending - I just checked. (The numbers don't go that high yet).
[I was looking to update the Security page, but can't find the
appropriate refs.]
Best Regards, Simon Riggs
| From | Date | Subject | |
|---|---|---|---|
| Next Message | David Fetter | 2006-01-09 09:29:33 | == PostgreSQL Weekly News - January 08 2006 == | 
| Previous Message | Marc G. Fournier | 2006-01-09 06:33:40 | CRITICAL RELEASE: Minor Releases to Fix DoS Vulnerability | 
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Markus Bertheau | 2006-01-09 09:30:08 | Re: [ANNOUNCE] CRITICAL RELEASE: Minor Releases to Fix DoS | 
| Previous Message | Magnus Hagander | 2006-01-09 09:25:57 | Re: Unregister Windows Service pg_ctl error | 
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Markus Bertheau | 2006-01-09 09:30:08 | Re: [ANNOUNCE] CRITICAL RELEASE: Minor Releases to Fix DoS | 
| Previous Message | Magnus Hagander | 2006-01-09 08:35:28 | Re: Release Announcement News Item -- please read |